US2021297433A1PendingUtilityA1

Method and apparatus for preventing network attack

Assignee: HUAWEI TECH CO LTDPriority: Feb 1, 2019Filed: Jun 3, 2021Published: Sep 23, 2021
Est. expiryFeb 1, 2039(~12.5 yrs left)· nominal 20-yr term from priority
H04L 2101/622H04L 61/103H04L 63/126H04L 12/4641H04L 63/0272H04L 63/1441H04L 63/1416H04L 63/1408H04L 63/162H04L 63/0876H04L 61/6022
40
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method for preventing a network attack, including: receiving, by a first network node in a Ethernet virtual private network (EVPN), a first packet, where the first packet carries a first media access control (MAC) address, and the first MAC address is a source MAC address of the first packet; and determining first MAC entry information, where the first MAC entry information includes a correspondence between the first MAC address, an identifier of the first MAC address, and egress port information of the first MAC address, and the identifier of the first MAC address is used to indicate that an egress port corresponding to the first MAC address is a trusted port. This method can reduce a risk that the EVPN breaks down caused by attacking the EVPN by an attacker.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A method for preventing a network attack, wherein the method is used in an Ethernet virtual private network (EVPN), the EVPN comprises a plurality of network nodes, and the method is performed by a first network node in the plurality of network nodes and comprises:
 receiving a first packet, wherein the first packet carries a first media access control (MAC) address, and the first MAC address is a source MAC address of the first packet; and   determining first MAC entry information, wherein the first MAC entry information comprises a correspondence between the first MAC address, an identifier of the first MAC address, and egress port information of the first MAC address, and the identifier of the first MAC address is used to indicate that the first MAC address is trusted.   
     
     
         2 . The method according to  claim 1 , wherein the first packet is received from a first port of the first network node, and the determining of the first MAC entry information comprises:
 determining that the first port is configured as a trusted port; and   determining the first MAC entry information based on the first MAC address and the egress port information of the first MAC address, wherein the egress port information of the first MAC address indicates the first port.   
     
     
         3 . The method according to  claim 2 , wherein the determining of the first MAC entry information based on the first MAC address and the egress port information of the first MAC address comprises:
 determining that pre-stored second MAC entry information does not comprise the first MAC address, or comprises the first MAC address but does not comprise the egress port information of the first MAC address;   updating the second MAC entry information; and   determining updated second MAC entry information as the first MAC entry information.   
     
     
         4 . The method according to  claim 2 , wherein the determining of the first MAC entry information based on the first MAC address and the egress port information of the first MAC address comprises:
 determining that pre-stored second MAC entry information comprises the first MAC address and the egress port information of the first MAC address; and   determining the second MAC entry information as the first MAC entry information.   
     
     
         5 . The method according to  claim 1 , wherein the first packet is received from a first port of the first network node, and the determining of the first MAC entry information comprises:
 determining that the first port is not configured as a trusted port;   determining that pre-stored second MAC entry information comprises a MAC address that is the same as the first MAC address;   determining that an identifier of the MAC address that is the same as the first MAC address indicates that the MAC address is trusted; and   determining the second MAC entry information as the first MAC entry information.   
     
     
         6 . The method according to  claim 1 , further comprising:
 sending a second packet to a network node other than the first network node in the EVPN, wherein the second packet carries the first MAC address and the identifier of the first MAC address.   
     
     
         7 . The method according to  claim 6 , wherein an identifier of each MAC address comprised in the second packet is carried in a reserved bit of the second packet. 
     
     
         8 . The method according to  claim 2 , wherein the method further comprises:
 sending a second packet to a network node other than the first network node in the EVPN, wherein the second packet carries the first MAC address and the identifier of the first MAC address.   
     
     
         9 . The method according to  claim 3 , further comprising:
 sending a second packet to a network node other than the first network node in the EVPN, wherein the second packet carries the first MAC address and the identifier of the first MAC address.   
     
     
         10 . The method according to  claim 4 , further comprising:
 sending a second packet to a network node other than the first network node in the EVPN, wherein the second packet carries the first MAC address and the identifier of the first MAC address.   
     
     
         11 . An apparatus for preventing a network attack, wherein the apparatus is configured in an Ethernet virtual private network (EVPN) and comprises:
 a memory, configured to store a program code, wherein   the memory is connected to at least one processor, and when the program code is executed by the at least one processor, the first device is caused to:   receive a first packet, wherein the first packet carries a first media access control (MAC) address, and the first MAC address is a source MAC address of the first packet; and   determine first MAC entry information, wherein the first MAC entry information comprises a correspondence between the first MAC address, an identifier of the first MAC address, and egress port information of the first MAC address, and the identifier of the first MAC address is used to indicate that the first MAC address is trusted.   
     
     
         12 . The apparatus according to  claim 11 , wherein the first packet is received from a first port of the apparatus, and wherein the first device is further caused to:
 determine that the first port is configured as a trusted port; and   determine the first MAC entry information based on the first MAC address and the egress port information of the first MAC address, wherein the egress port information of the first MAC address indicates the first port.   
     
     
         13 . The apparatus according to  claim 12 , wherein the first device is further caused to:
 determine that pre-stored second MAC entry information does not comprise the first MAC address, or comprises the first MAC address but does not comprise the egress port information of the first MAC address;   update the second MAC entry information; and   determine updated second MAC entry information as the first MAC entry information.   
     
     
         14 . The apparatus according to  claim 12 , wherein the first device is further caused to:
 determine that pre-stored second MAC entry information comprises the first MAC address and the egress port information of the first MAC address; and   determine the second MAC entry information as the first MAC entry information.   
     
     
         15 . The apparatus according to  claim 11 , wherein the first packet is received from a first port of the apparatus, and the first device is further caused to:
 determine that the first port is not configured as a trusted port;   determine that pre-stored second MAC entry information comprises a MAC address that is the same as the first MAC address;   determine that an identifier of the MAC address that is the same as the first MAC address indicates that the MAC address is trusted; and   determine the second MAC entry information as the first MAC entry information.   
     
     
         16 . The apparatus according to  claim 11 , wherein the first device is further caused to:
 send a second packet to a network node other than the first network node in the EVPN, wherein the second packet carries the first MAC address and the identifier of the first MAC address.   
     
     
         17 . The apparatus according to  claim 16 , wherein an identifier of each MAC address comprised in the second packet is carried in a reserved bit of the second packet. 
     
     
         18 . The apparatus according to  claim 12 , wherein the first device is further caused to:
 send a second packet to a network node other than the first network node in the EVPN, wherein the second packet carries the first MAC address and the identifier of the first MAC address.   
     
     
         19 . The apparatus according to  claim 13 , wherein the first device is further caused to:
 send a second packet to a network node other than the first network node in the EVPN, wherein the second packet carries the first MAC address and the identifier of the first MAC address.   
     
     
         20 . The apparatus according to  claim 14 , wherein the first device is further caused to:
 send a second packet to a network node other than the first network node in the EVPN, wherein the second packet carries the first MAC address and the identifier of the first MAC address.

Join the waitlist — get patent alerts

Track US2021297433A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.